10/01/2026 | Press release | Distributed by Public on 10/01/2026 12:00
Every AI security vendor says the same thing: we protect your models, your agents, your pipeline. Fewer say clearly how that protection fits into the way your team actually works.
Security teams are not one thing. Some want a dedicated home for this work: a secure console where models, agents, and detections reside within a single purpose-built system. Others already run a security operation built on their own tooling and want raw findings fed into a single pane of glass they control, not a dashboard someone else designed for them. HiddenLayer is built for both.
That means showing up where the work already happens.
If you build on cloud infrastructure, we are there before a model reaches production. Our AI Supply Chain module checks models onboarded to Microsoft's Azure AI Foundry catalog for tampering, backdoors, and known vulnerabilities, as confirmed on Microsoft's own product blog. On AWS, we cover Bedrock, Bedrock Agents, SageMaker, and agents built on the Strands framework. Inside Databricks, model scanning runs automatically against Unity Catalog, so a new model version gets checked the moment it lands, not the next time someone remembers to ask.
If you ship through a pipeline, we are in it. HiddenLayer plugs into GitHub Actions, Jenkins, Azure DevOps, and JFrog Artifactory, scanning models the way a dependency scanner checks a library: automatically, at the point they enter your build, before a security team has to go looking for them.
If your SOC lives in Splunk or Microsoft Sentinel, our detections show up there, too. Nobody has to learn a new tool to see what we found.
If you are building agents, we sit at the framework level. LangChain, LiteLLM, the OpenAI Agents SDK, AWS Strands, and TrueFoundry's gateway all carry HiddenLayer guardrails natively, so coverage does not depend on which stack a team happened to choose.
And if your developers write code with Cursor, Claude Code, or GitHub Copilot, our Agent Harness Security solution integrates with each one's native hook surface, because the harness wrapped around a coding agent, not the model inside it, is where the attacks we've studied against coding agents keep landing.
AI security doesn't hold still long enough for anyone to coast on a single audit. What we know about it comes from continually taking these systems apart ourselves. Our research team has spent years doing exactly that and continues to do so as new agents ship. We found that Cursor could be manipulated through a hidden prompt injection buried in a project's README.md, chained to an XML-tag trust exploit, to leak API keys and SSH credentials, and built a live demonstration showing our AI Runtime Security blocking that exact attack. We traced the same failure pattern, misplaced trust in the layers wrapping a model, across five distinct points in a coding agent's harness, and used that map to decide what Agent Harness Security actually needed to watch.
We also ask the people living through this directly. Our 2026 AI Threat Landscape Report surveyed 250 IT and security leaders and found that malware hidden in public model and code repositories is now the single most-cited source of AI-related breaches, at 35 percent, even though 93 percent of organizations still pull models from them. One in eight reported AI breaches now involves an agentic system. Those two numbers are why we scan Hugging Face repositories directly, and why coding agents got their own dedicated security layer instead of a footnote in a bigger product.
This list isn't finished. New agents and platforms ship every quarter, and we intend to keep showing up in them. Over the next several weeks, we'll go deeper on each one, starting with the clouds and the pipelines and ending with the coding agents themselves. But the pattern holds no matter which box on this list you're standing in: we'd rather build the thing that fits how you already work than ask you to change how you work to fit us.